|
257011
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
|
CWE-862
Missing Authorization
|
CVE-2017-1002007
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257012
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
|
CWE-862
Missing Authorization
|
CVE-2017-1002006
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257013
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
|
CWE-89
SQL Injection
|
CVE-2017-1002005
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257014
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
|
CWE-89
SQL Injection
|
CVE-2017-1002004
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257015
|
9.8 |
CRITICAL
Network
|
wp2android-turn-wp-site-into-android-app_project
|
wp2android-turn-wp-site-into-android-app
|
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002003
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257016
|
9.8 |
CRITICAL
Network
|
webapp-builder_project
|
webapp-builder
|
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002002
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257017
|
9.8 |
CRITICAL
Network
|
mobile-app-builder-by-wappress_project
|
mobile-app-builder-by-wappress
|
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002001
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257018
|
9.8 |
CRITICAL
Network
|
mobile-friendly-app-builder-by-easytouch_project
|
mobile-friendly-app-builder-by-easytouch
|
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002000
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257019
|
8.0 |
HIGH
Adjacent
|
linux debian nvidia redhat
|
linux_kernel debian_linux jetson_tk1 jetson_tx1 enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_…
|
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000251
|
2024-11-21 12:04 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257020
|
6.5 |
MEDIUM
Adjacent
|
bluez
|
bluez
|
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd pr…
|
CWE-200
Information Exposure
|
CVE-2017-1000250
|
2024-11-21 12:04 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|